SaaS

SaaS Release Notes - September 4, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat’s new

SaaS Connectors - Spacelift SaaS

Identity Security Connectivity now supports the Spacelift SaaS connector. For more information, refer to Integrating SailPoint with Spacelift.

SaaS Connectors - AWS SaaS

The AWS SaaS connector now supports agent discovery for Amazon Connect Customer, in addition to the existing Amazon Bedrock and Amazon Bedrock AgentCore agents. The connector aggregates Amazon Connect Customer instances, domains, AI agents, knowledge bases, prompts, guardrails, tools, and security profiles. For more information, refer to Integrating SailPoint and Amazon Web Services SaaS.

SaaS Connectors - Bitbucket Cloud SaaS

The Bitbucket Cloud SaaS connector is now available in Identity Security Cloud. The connector supports:

  • Account aggregation for Bitbucket workspace members
  • Entitlement aggregation for Bitbucket groups from the Atlassian organization
  • Extended visibility into non-human identities (NHIs) by aggregating project deploy keys, repository deploy keys, and pipeline variables

This connector is read-only and does not support provisioning.

For more information, refer to Integrating SailPoint with Bitbucket Cloud.

SaaS Connectors - CircleCI SaaS

The CircleCI SaaS connector is now available in Identity Security Cloud. The connector extends visibility into non-human identities (NHIs) by aggregating checkout keys, SSH keys, and deploy keys. This connector is read-only and does not support provisioning.

For more information, refer to Integrating SailPoint with CircleCI.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Connectivity - N8N

The N8N connector is now available. The connector supports

  • Account and entitlement aggregation for N8N platform users and team projects.
  • Extended visibility into non-human identities (NHIs) by aggregating workflows, AI agents, tools, MCP clients, MCP servers, and stored credentials.

For more information, refer to Integrating SailPoint with N8N.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Identity Security Cloud - SoD

FedRAMP customers licensed for Separation of Duties now have access to SoD Violation Management and SoD Violation Controls. For details, refer to Creating and Editing SoD Controls and Handling Policy Violations.

Enhancements

ProductFeature enhancements

SaaS Connectors - Oracle HCM Cloud SaaS

The Oracle HCM Cloud SaaS connector now supports the following employee feeds:

  • Person Work Relationship Canceled (cancelworkrelship) – Captures the cancellation of a worker’s period of service.
  • Employee Work Relationship Updated (workrelshipupdate) – Captures updates to a worker’s work relationship.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now batches all CSA updates into a single Microsoft Graph API request, eliminating sleep-based workarounds. This improves provisioning speed, reliability, and scalability.

Connectivity - Microsoft Entra ID

The Microsoft Entra ID connector now uses the Azure Resource Graph API to aggregate both resource-attached and policy-assigned system-assigned managed identities (SAMIs) in a single request, ensuring complete managed identity coverage.

SaaS Connectors - Salesforce SaaS

The Salesforce SaaS connector now supports provisioning the IsFrozen attribute during update operations.

Connectivity - SalesForce

SaaS Connectors - Salesforce SaaS

The Salesforce connector now persists Salesforce-rotated refresh tokens and renews access tokens automatically for sources configured with External Client Application authentication. This prevents reauthorization prompts following concurrent aggregation or provisioning operations.

Migrate your Salesforce source to External Client Application authentication to use this enhancement. For migration details, refer to Announcement: ISC Salesforce Connector Migration to External Client App and Announcement: Salesforce External Client App is now Available.

Connectivity - Oracle HCM Cloud

The Oracle HCM Cloud connector now supports the following employee feeds:

  • Person Work Relationship Canceled (cancelworkrelship) – Captures the cancellation of a worker’s period of service.
  • Employee Work Relationship Updated (workrelshipupdate) – Captures updates to a worker’s work relationship.

Identity Security Cloud - SoD

Separation of duties permissions can now be included in custom user levels. Refer to Custom User Level Matrices for details.

Identity Security Cloud - Workflows

Workflows recommends adding trigger filters to all filterable trigger steps to prevent unintended high-executions causing workflow limits to be reached.

While configuring a workflow, a validation error displays if your trigger filter is invalid, either because the JSONPath syntax is incorrect or because the filter doesn’t meet the requirements.

While testing a workflow, a warning icon displays on the trigger step if no filter has been configured, and an error message displays if the configured filter will not result in the workflow being triggered.

SaaS Connectors - Application Visibility

Identity Security Cloud now lists browser extension discovered applications in a separate tab from SSO, CMDB, and PAM discovered applications. Additionally, unmanaged SaaS applications (Shadow IT) are now categorized by their security risk in the browser extension discovered applications tab.

Fixes

ProductIssue IDFixes

Connectivity - SAP SuccessFactors

CONETN-5473

The SailPoint SuccessFactors connector Fixed a timeout error in single account aggregation. The error occurred on sources with large Cost Center master data. It affected account schemas that included the CostCenter and CostCenterID attributes. The connector now retrieves only the Cost Center record that the aggregated account requires.

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-7529

The Microsoft Entra SaaS connector schema no longer lists associated resources, as system-assigned managed identities do not support associated resources.

Connectivity - ServiceNow

CONETN-5479

The ServiceNow Identity Governance connector now applies the configured connectionTimeout value to API requests. The default value is 180 seconds.

SaaS Connectors - Smartsheet

CONETN-5589

The Smartsheet SaaS connector now retries configured retryable errors during provisioning operations. HTTP 429 is the default retryable error.

For more information, refer to Integrating SailPoint with Smartsheet.

SaaS Connectors - Slack SaaS

CONETN-5457

Fixed an issue where the Slack SaaS connector omitted channels from the account after attribute synchronization or other provisioning updates. Channel entitlements could appear missing on the identity and Slack account until aggregation ran again.

Non-Employee Risk Management

TRIAGE-16094

Updated the Languages configuration page to use an edit link to change attribute name translations.

In addition, fixed an issue where some languages couldn’t be enabled, or enabling some languages would disable others.